The Offside Wallet Theft Factory Firefox Add-ons

Updated 5 Oct 2026 · Incident date 9 Mar 2026 · browser extension

Package9 Firefox add-on IDs first published as sports-score tools, later updated into fake OKX / Rabby / TronLink wallet stealers (part of 77 tracked identities)
Filenot named by Socket, but version pairs are published, e.g. bright-save-feed@tabtools.org v7.4.0

Nine Firefox add-on IDs, first published as harmless sports-score tools, were later updated into fake Rabby wallet add-ons that steal recovery phrases. Socket named the campaign the Offside Wallet Theft Factory and linked 77 add-on identities to it.

Mozilla signing records for the campaign run from 9 March to 3 August 2026. Socket did not identify confirmed victims or total losses.

What happened

Operators published add-ons that looked like sports tools, then pushed updates under the same Firefox IDs that carried wallet-stealing code. Socket's report counts 77 linked identities. Of these, 40 are confirmed malicious and 37 are sports-score shells. The shells advertised unrelated functions such as password generation, VPN, screenshots and note-taking, but showed sports scores.

Nine of the malicious IDs began as sports-score shells for football, basketball, NBA or American football. Later versions under the same IDs became fake wallets that impersonate Rabby, OKX or TronLink. A user who installed the harmless version received the update through the normal add-on update path.

Socket groups the 40 malicious add-ons by method.

CryptoSlate and CyberInsider report the same counts and the same March to August 2026 window.

Affected versions

Nine Firefox IDs are confirmed to have changed from a sports version to a wallet-stealing version. Socket lists these pairs.

Firefox IDSports versionMalicious version
bright-save-feed@tabtools.orgQuick Quick 7.4.0Rabbit For Desktop 8.20.10
swift-clip-link@fasttools.coDial Open Pro 7.23.25Web3 & EVM 9.50.10
deep-tip-sharp@browsify.coQuick Shield 5.7.1Rby-WALLET 6.7.10
bolt-save-vault@devplugs.coLite Swatch 6.5.21abby-WALLET 7.10.10
core-note-nova@webtools.netKey Pulse 8.1.21RABB-Wallet 8.22.30
gear-save-tip@extrakits.exampleTimer Pulse 5.5.5Rabbit WALLET 11.10.10
flex-lab-save@foxplugin.coTrack Quick 6.10.24RabbWALLET 7.10.30 and 8.10.30
pure-net-snap@fasttools.coStore Plus 8.3.18Rabb WALLET 9.11.30
fast-zip-true@smartext.coPomodoro Plus 9.13.24RABB-WALLET 10.20.10

Socket's names use look-alike characters, so the table shows plain forms. Match on the Firefox ID. Mozilla removed live add-ons during the investigation.

Indicators of compromise

Socket lists these indicators. Defanged forms are written as in the report.

How to check

List your installed Firefox add-ons and search for the nine IDs. On macOS, this command reads your profile data and changes nothing. On Linux, use ~/.mozilla/firefox as the path.

grep -lE "bright-save-feed@tabtools.org|swift-clip-link@fasttools.co|deep-tip-sharp@browsify.co|bolt-save-vault@devplugs.co|core-note-nova@webtools.net|gear-save-tip@extrakits.example|flex-lab-save@foxplugin.co|pure-net-snap@fasttools.co|fast-zip-true@smartext.co" ~/Library/Application\ Support/Firefox/Profiles/*/extensions.json

A file name in the output means one of the IDs is or was installed in that profile. Also open about:support in Firefox and read the Extensions list for any wallet add-on you did not install on purpose.

What to do now

  1. Remove any matching add-on from Firefox.
  2. If you typed a recovery phrase or private key into one of these add-ons, treat it as stolen. Socket states that removing the add-on cannot revoke a secret that was already sent.
  3. Create a new wallet from a new recovery phrase and move your remaining assets to it.
  4. If only credentials or clipboard contents were exposed, change the passwords, end active sessions and check destination addresses before you send funds.
  5. Review add-on activity after each update, because these add-ons changed after install.

This case shows an update that adds a new capability to an artifact that was clean before. Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See the full attack list and download Vigilance.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old 9-prev --new 9-current
files scanned: 73 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   background.js
           It downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

What is the Offside Wallet Theft Factory?

It is the name Socket gave to a campaign of 77 linked Firefox add-on identities. Forty are confirmed malicious wallet stealers and 37 are sports-score shells. Mozilla signing records run from 9 March to 3 August 2026.

How did harmless Firefox add-ons become wallet stealers?

Nine add-on IDs first shipped as sports-score tools. Later updates under the same Firefox IDs replaced them with fake Rabby and other wallet add-ons that capture recovery phrases and send them out.

What do I do if I entered a recovery phrase into one of these add-ons?

Treat the phrase as stolen. Create a new wallet from a new recovery phrase and move your remaining assets to it. Removing the add-on does not revoke a secret that was already sent.

Sources

  1. socket.dev/blog/firefox-crypto-wallet-theft
  2. cryptoslate.com/firefox-crypto-wallet-malware-hid-behind-nine-sports-add-ons-turning-routine-updates-into-a-key-rotation-trap/
  3. cyberinsider.com/40-malicious-firefox-extensions-caught-stealing-crypto-wallet-data/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free